Skip to content

Fix RSA constant-time padding and length checks - #710

Open
iamnoksio wants to merge 2 commits into
RustCrypto:masterfrom
iamnoksio:master
Open

iamnoksio wants to merge 2 commits into
RustCrypto:masterfrom
iamnoksio:master

Conversation

@iamnoksio

Copy link
Copy Markdown

This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.

This change removes variable-time padding behavior by writing into fixed-width buffers instead of slicing based on secret leading-zero counts. It also enforces the RFC 8017 ciphertext-length check before PKCS#1 v1.5 decryption and avoids variable-time Montgomery reduction on private-key paths. The patch adds regression tests covering padding edge cases, PKCS#1 v1.5 length rejection, and Montgomery reduction correctness.
Comment thread src/algorithms/pad.rs Outdated
Comment thread src/algorithms/pkcs1v15.rs Outdated
@tarcieri

Copy link
Copy Markdown
Member

Overall I like the direction of this PR, thanks

Comment thread src/algorithms/pad.rs
let (hi, lo) = bytes.split_at(bytes.len() - padded_len);
let overflow = hi.iter().fold(0u8, |acc, b| acc | b);
out.copy_from_slice(lo);
if core::hint::black_box(overflow) != 0 {

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This seems value-dependent? I'm also not sure what black_box is buying you here.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yup agreed on both black_box was really just an optimizer hint anyway I'm gonna push soon to address this

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants